Splunk Search

How to search field from log1 in to match in log2 and display field in log1 and log2 in table?


Hello Everyone.

I wonder if anyone could help me with a report I'm trying to make.

Below is my sample logs format.

log1 example.

ipfield sessionfield - - timefield urlfield methodfield 

log2 example

datefied midfield sessionfield2 sessionfield3 userfield functionfield ipfield2 rolefield.


what I want to do is search log2 if the sessionfield in log1 exists, then print out a table that has 

userfield from log2, ipfield from log1orlog2, all sessionfield from log1 and log2,   userfield from log2, urlfield and mehtodfield and the counts of methodfield.


I have something like this 

(index=1 log2) OR (index=1 log1)| eval sessionfield=coalesce(sessionfield,sessionfield2,sessionfield3) | stats values(sessionfield) values(ipfield2) by sessiontuser

I got the sessionfield(s) to print but it did not print the sessionfield in log1.

I could not figure out how to print the other fields that I needed 

I don't have much experience in Splunk search so any guidance or help would be excellent.

thank you.



Labels (5)
0 Karma


sorry my typo on the sessionuser, it suppose to be userfield in log2.

thank you for the wildcard query it helps me understand how coalesce works more.

0 Karma


There is no sessiontuser field in the example query so I'm not surprised it doesn't produce the desired results.  It's close, though.  Try this variation:

(index=1 log2) OR (index=1 log1)
| eval sessionfield=coalesce(sessionfield,sessionfield2,sessionfield3) 
| stats values(*) as * by sessionfield
If this reply helps you, an upvote would be appreciated.
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...